Jobs · Engineering · Washington

DevOps Engineer, Assurance and Infrastructure Services - USDS

TikTok USDS Joint Venture · Seattle, WA · 6 days ago
On-siteEngineering$130k–$246k/yrFull-time

About the Role

Our team owns the developer platform and release toolchain that powers TikTok’s US infrastructure. We focus on CI/CD pipelines, artifact repository management, and cloud deployment workflows, partnering closely with engineering teams and assurance partners (USDS/USTS, auditors) to make build, test, and release fast, secure, and compliant by design. You will design, build, and operate the critical tooling that developers use every day: CI/CD pipelines, artifact repositories, and deployment workflows across multiple environments.

Responsibilities

  • Own and Evolve CI/CD Pipelines: Design, build, and maintain CI/CD pipelines for backend and platform services, improving reliability, speed, and developer experience while embedding security and compliance checks.
  • Secure Supply Chain Management: Implement and manage software supply chain security controls, including SBOM generation and validation, artifact signing and attestation (e.g., SLSA), and provenance tracking to ensure the integrity of the build and release process.
  • Automate Policy-as-Code Gates: Integrate and enforce automated security and compliance gates within CI/CD pipelines, such as secrets scanning, dependency risk analysis, license compliance checks, and vulnerability scanning, with fail-safe promotion rules.
  • Ensure Auditability and Evidence Collection: Design and operate systems for comprehensive auditability, including immutable change logs, deployment records, and traceable rollbacks. Support internal and external assurance requests by providing clear, auditable evidence.
  • Manage Cloud IAM and Secrets: Design and enforce least-privilege access controls in OCI/cloud environments. Implement best practices for role design, key/secrets hygiene, and periodic access reviews to minimize security risks.
  • Enhance System Resilience and Disaster Recovery: Align release tooling with Risk, Disaster Recovery (DR), and Business Continuity Planning (BCP) requirements. Implement and periodically test backup and restore procedures for critical repositories and pipelines.
  • Develop and Maintain Incident Playbooks: Create, document, and rehearse incident response playbooks for build/deploy failures and security events. Lead postmortems and drive corrective actions to prevent recurrence.
  • Design and Maintain Deployment Workflows: Standardize deployment workflows (e.g., blue/green, canary, automated rollout/rollback) in a major cloud environment (OCI preferred).
  • Manage Artifact Repositories: Administer artifact repositories (e.g., Artifactory) including layout, permissions, retention policies, and housekeeping to ensure build reproducibility and integrity.

Requirements

Minimum Qualifications

  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical experience.
  • Solid software engineering skills with one or more programming languages (e.g., Python, Go, Java).
  • Hands-on experience building and maintaining CI/CD pipelines using systems like GitLab CI, Jenkins, or similar.
  • Experience with at least one major cloud provider (OCI, AWS, GCP), with a strong understanding of IAM concepts.
  • Practical experience with artifact repositories (e.g., JFrog Artifactory, Nexus) for container images and language packages.
  • Experience integrating security scanning tools (e.g., for dependencies, vulnerabilities, secrets) into CI/CD pipelines.
  • Good communication skills and the ability to work closely with developers and partner teams.

Preferred Qualifications

  • Experience working within compliance-heavy environments and supporting audits (e.g., SOC2, ISO 27001, PCI).
  • Expertise in designing and implementing software supply chain security measures, such as code signing, SBOM tools (e.g., Syft, Grype), and artifact attestation frameworks (e.g., SLSA).
  • Deep experience with OCI, including advanced IAM, and automating infrastructure and deployments.
  • Experience in platform or developer productivity teams, building internal tools and templates for other engineers.
  • Familiarity with containerization (Docker, Kubernetes) and its security ecosystem.
  • A demonstrated track record of writing clear technical documentation for security processes and runbooks.

About the Team

TikTok USDS Joint Venture LLC is dedicated to the safety and security of millions of Americans who create, discover, and connect with what they love on the apps we operate. The Joint Venture has been established in compliance with the Executive Order signed by President Trump on September 25, 2025. Our foundation is a comprehensive data privacy and cybersecurity program we operate under defined safeguards to protect national security and secure U.S. user data, apps, and the algorithm. We safeguard the U.S. content ecosystem, holding decision-making authority for trust and safety policies and moderation.

On-site presence across teams allows the company to operate with greater speed, alignment, and agility — especially in areas like real-time decision-making, team development, and integrated execution. As such, the company is shifting from a hybrid work model to a fully in-person schedule up to 5 days a week.

Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect — and our global, diverse teams make that possible. We strive to do great things with great people, leading with curiosity, humility, and a desire to make an impact. Every challenge is an opportunity to learn and innovate as one team, embracing an "Always Day 1" mindset to achieve meaningful breakthroughs.

Benefits

  • Day one access to medical, dental, and vision insurance.
  • 401(k) savings plan with company match.
  • Paid parental leave, short-term and long-term disability coverage, and life insurance.
  • Wellbeing benefits.
  • 10 paid holidays per year.
  • 10 paid sick days per year.
  • 17 days of Paid Personal Time (prorated upon hire with increasing accruals by tenure).

Pay

The base salary range for this position in the selected city is $129,960 - $246,240 annually. Compensation may vary outside of this range depending on qualifications, skills, competencies, experience, and location. Base pay is one part of the total package that may include additional discretionary bonuses/incentives and restricted stock units.

Schedule

Fully in-person schedule up to 5 days a week.

Similar jobs